Sceawere

Vulnerability Detail

CVE-2026-105113UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Nezha Dashboard Mutex Deadlock Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
2h ago
Vendor
nezhahq
Product
nezha
Attack Type
Improper Locking
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Nezha Dashboard from 1.8.0 before 2.3.13 contains an improper locking vulnerability where a non-deferred mutex unlock leaks on a nil-map panic path. Any authenticated non-admin member can issue four notification API calls to permanently deadlock the alerting subsystem, then exhaust memory with blocking requests.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-03T14:16:37.823Z",
  "pubdate": "2026-10-03T14:16:37.823Z",
  "executiveSummary": "Nezha Dashboard versions 1.8.0 through 2.3.12 are susceptible to an improper locking vulnerability within the alerting subsystem.\nThe flaw stems from a non-deferred mutex unlock occurring on a nil-map panic path, which leads to a permanent deadlock of the notification engine.\nAn authenticated non-admin attacker can exploit this condition by issuing a sequence of four specific notification API calls, effectively disabling alerting functionality for the entire system.\nFollowing the initial deadlock, the application becomes vulnerable to memory exhaustion as blocking requests accumulate in the service queue.\nThis vulnerability poses a significant denial-of-service (DoS) risk, as it permits low-privileged users to disrupt critical monitoring and alerting workflows while potentially compromising system stability through heap memory pressure.\nSuccessful exploitation requires valid authentication to the dashboard, but does not necessitate administrative privileges, broadening the threat landscape to include any registered user.",
  "technicalDetails": "The vulnerability resides in the concurrency management logic of the Nezha Dashboard alerting subsystem. The root cause is a race condition and error-handling deficiency where a sync.Mutex is released without the use of a defer statement during a panic sequence triggered by a nil-map access.\nUnder normal operations, the alerting service utilizes a mutex to synchronize access to notification state objects. When an unexpected condition triggers a nil-map dereference, the runtime panics. Because the mutex unlock operation is not wrapped in a defer block, the unlocking call is bypassed when the execution flow is interrupted by the panic. This results in the mutex remaining in a permanently locked state.\nAn attacker can exploit this by triggering the specific code path associated with the notification API. By sending four carefully crafted notification API requests, the attacker induces the panic condition, causing the alerting subsystem to halt. Once the mutex is leaked in an locked state, all subsequent attempts by the application to access the alerting subsystem result in threads blocking indefinitely as they wait to acquire the held lock.\nThe attack flow follows these steps: 1. The attacker authenticates to the Nezha Dashboard. 2. The attacker submits a series of four malicious or malformed notification-related API requests. 3. The server-side logic triggers a nil-map dereference, which initiates a panic. 4. Due to the lack of a deferred mutex unlock, the synchronization primitive is left in a locked state during the panic recovery or process crash handling. 5. The alerting subsystem becomes unresponsive, and subsequent incoming requests to the alerting module are queued and blocked.\nThe post-exploitation impact extends beyond the loss of alerting functionality. Because the incoming requests to the alerting service are blocked and held in memory, the application experiences a rapid increase in memory consumption. If sustained, this leads to heap exhaustion, potentially causing the entire Nezha Dashboard process to crash, resulting in a full denial-of-service condition.\nThis vulnerability affects Nezha Dashboard versions from 1.8.0 up to 2.3.12. It is highly exploitable by any authenticated user who has access to the notification API endpoints, as no further administrative privileges are required to reach the vulnerable code path."
}